1.6 Risk Categories and Risk Management vs. Risk Assessment

Key Takeaways

  • PECB Domain 1 explicitly names four risk types: strategic, financial, compliance, and operational risk.
  • Systematic risk is market-wide and non-diversifiable (interest rate, exchange, inflation), whereas unsystematic risk is entity-specific and diversifiable (operational, business, credit risk of one firm).
  • Risk assessment is only the middle portion of the ISO 31000 process: risk identification, risk analysis, and risk evaluation.
  • Risk management is the whole discipline - principles, framework, and process - and includes treatment, monitoring, recording, reporting, and communication.
  • Confusing risk management with risk assessment is a named PECB competency, and a frequent source of distractors.
Last updated: July 2026

1.6 Risk Categories and Risk Management vs. Risk Assessment

Two Domain 1 competencies are examined together often enough to be worth studying together: the ability to distinguish between various types of risk, and the ability to distinguish between risk management and the risk assessment process. Both are definitional, both are cheap marks, and both are frequently lost to plausible-sounding distractors.


The Four Risk Types Named in Domain 1

PECB's Domain 1 knowledge statements explicitly list strategic, financial, compliance, and operational risk. These are the categories an ISO 31000 risk taxonomy is normally built on.

Risk typeDefinitionTypical examplesUsual owner
StrategicRisk arising from the organization's chosen direction and its ability to execute itFailed market entry, disruptive competitor, poor merger integration, obsolete business modelBoard / CEO
FinancialRisk to capital, liquidity, earnings, and asset valuesCredit default, liquidity shortfall, currency and interest-rate movement, investment lossCFO / Treasurer
ComplianceRisk of breaching laws, regulations, contracts, or internal policyGDPR breach, sanctions violation, licence loss, contractual non-performanceChief Compliance Officer
OperationalRisk from inadequate or failed internal processes, people, systems, or external eventsProcess failure, fraud, system outage, supply chain disruption, safety incidentOperational management

Many taxonomies add reputational, cyber, project, and ESG/climate risk. These are usually treated as cross-cutting consequences or sub-categories rather than as a fifth peer category — reputational damage, for example, is normally a consequence of a compliance, operational, or strategic event rather than a source in its own right.


Systematic vs. Unsystematic Risk

This pair comes from financial risk theory and appears in PECB scenario questions.

  • Systematic risk (also called market risk or non-diversifiable risk) affects an entire market or economy. No amount of portfolio diversification removes it. Examples: interest rate risk, exchange rate risk, inflation risk, recession, political and geopolitical risk.
  • Unsystematic risk (also called specific, idiosyncratic, or diversifiable risk) is confined to one entity, sector, or asset. It can be materially reduced by diversification. Examples: operational risk, business risk, a single firm's credit risk, a product recall, a key-person departure, a plant fire.

Exam Tip: A published PECB sample question asks for an example of unsystematic risk, offering exchange risk, interest rate risk, and operational risk. The answer is operational risk — exchange and interest rate risk are both market-wide and therefore systematic.


Pure vs. Speculative Risk

A second classical pair worth holding:

  • Pure risk admits only loss or no loss — fire, theft, natural catastrophe, workplace injury. Pure risks are the classic subject of insurance.
  • Speculative risk admits gain, loss, or no change — a new product launch, an acquisition, a currency position, an R&D programme.

ISO 31000:2018 spans both. Because risk is defined as the effect of uncertainty on objectives, and an effect is a deviation from the expected that may be positive, negative, or both, ISO 31000 explicitly refuses to restrict risk management to pure downside risk. This is why taking or increasing risk to pursue an opportunity is one of the standard's treatment options.


Risk Management vs. Risk Assessment

This is the distinction PECB names as its own competency, and it is the one candidates most often get wrong under time pressure.

Risk assessment is defined in ISO 31000:2018 Clause 6.4 as the overall process of risk identification, risk analysis, and risk evaluation — three steps and no more. It answers: what could happen, how bad and how likely is it, and does it matter enough to act on?

Risk management is the whole discipline: coordinated activities to direct and control an organization with regard to risk. Under ISO 31000 it comprises three architectural layers:

  1. Principles (Clause 4) — the eight characteristics of effective risk management, centred on value creation and protection.
  2. Framework (Clause 5) — leadership and commitment, integration, design, implementation, evaluation, improvement.
  3. Process (Clause 6) — communication and consultation; scope, context and criteria; risk assessment; risk treatment; monitoring and review; recording and reporting.
Risk assessmentRisk management
ScopeThree activities within one process stepPrinciples, framework, and the entire process
Clause6.4 onlyThe whole standard
Includes treatment?NoYes
Includes governance and leadership?NoYes
OutputA prioritized, evaluated risk pictureA sustained, integrated organizational capability

Exam Trap: A distractor that describes "identifying, analyzing, evaluating, and treating risks" is describing neither term cleanly — treatment sits outside risk assessment. Likewise, an option claiming risk management is "a synonym for risk assessment" is always wrong.


The Main Elements of Risk Management

When a question asks for the main elements of risk management under ISO 31000, the expected answer is the tripartite architecture — principles, framework, process — supported by:

  • A defined risk management policy approved by top management.
  • Assigned roles, authorities, responsibilities, and accountabilities, including risk owners.
  • Allocated resources — people, budget, tools, information, and training.
  • Established risk criteria reflecting appetite, objectives, and obligations.
  • Communication and consultation running throughout, not bolted on at the end.
  • Monitoring, review, recording, and reporting to close the improvement loop.
Loading diagram...
Risk Management vs. Risk Assessment: Scope Comparison
Test Your Knowledge

Which of the following is an example of unsystematic risk?

A
B
C
D
Test Your Knowledge

Under ISO 31000:2018, which activities make up the risk assessment process?

A
B
C
D
Test Your Knowledge

A regulator fines an organization after it fails to file a mandatory disclosure required by statute. Using the four risk categories named in the PECB Domain 1 syllabus, how is this risk best classified?

A
B
C
D